|
w00w00 Security Advisory - http://www.w00w00.org/
Title: qmail-pop3d with vpopmail/vchkpw |
| 1. Overview
qmail-pop3d may pass an overly long command argument to its password
2. Background It is Qmail's nonconformance to the pop3 specification that allows >From RFC1939 [Post Office Protocol - Version 3] |
| Commands in the POP3 consist of a caseinsensitive keyword,
possibly followed by one or more arguments. All commands are terminated by a CRLF pair. Keywords and arguments consist of printable ASCII characters. Keywords and arguments are each separated by a single SPACE character. Keywords are three or four characters long. Each argument may be up to 40 characters long. -------------------------------------------------------- >From BLURB3 (qmail-1.03) |
| 3. Issue
qmail-pop3d claims compliance to RFC1939, however this is not the case
|
| 4. Impact
A remote attacker may attain the privilege level of the authentication
module. 5. Recommendation Impose the 40 character limitation specified by RFC1939 into qmail, and vpopmail.
RFC1939 |
| K2 email me |